官术网_书友最值得收藏!

Generating authorized RSA keys

This recipe describes how to create an authorized RSA key so a user can connect to pfSense without being prompted for a password.

Getting ready

Linux and Mac users will need to ensure ssh-keygen is installed on their system (almost all distributions have this installed by default). Windows users will need to download and install the PuTTYGen tool.

How to do it...

Generate an SSH key from a Linux/Mac Client as follows:

  1. Open a terminal and run:
    ssh-keygen
    
  2. Save the key to the default location of /home/user/.ssh/ and specify a pass code (optional, but recommended).
  3. Your public key is now located at /home/user/.ssh/id_rsa.pub.

    Generate an SSH key from a Windows client using PuTTY as follows:

  4. Open PuTTYGen and generate a public/private key pair by clicking the Generate button.
  5. Enter a passphrase (optional, but recommended).
  6. Click the Save Private Key button and choose a location, such as C:\MyPrivateKey.ppk.
  7. Highlight the public key that was generated in the textbox and copy and paste it into a new file, let's say C:\MyPublicKey.txt. (Do not use the Save Public Key button, as that adds comments and other fields that are sometimes incompatible.)

How it works...

RSA keys have become a standard for securing client/server connections for any service which chooses to take advantage of it. A client generates a key pair—a private key file and a public key file (an optional pass-phrase can be specified for enhanced security). Now, any server administrator can request that client's public key and add it to their system. The client can then securely authenticate without typing in a password.

There's more...

RSA key authentication is most often associated with SSH access, and is often referred to as SSH keys but that is misleading. RSA keys are generic and not specific to SSH. Although SSH often uses them, RSA keys can be used by any type of service that chooses to support them, such as VPN, VoIP, FTP, and so on.

See also

  • The Enabling the Secure Shell (SSH) recipe
  • The Configuring SSH RSA key authentication recipe
主站蜘蛛池模板: 无棣县| 蒲江县| 突泉县| 上犹县| 堆龙德庆县| 晋中市| 高碑店市| 老河口市| 鄂州市| 新绛县| 竹山县| 绥江县| 肇庆市| 永昌县| 广宁县| 桃园市| 芦山县| 津南区| 德州市| 安义县| 南京市| 玉山县| 林芝县| 安宁市| 新野县| 徐汇区| 泾川县| 梧州市| 雷山县| 沈丘县| 平谷区| 津南区| 浦东新区| 宜宾市| 四平市| 务川| 当涂县| 惠州市| 于田县| 明溪县| 怀远县|